Microsoft expanded its security capabilities for code development and multicloud with new announcements under its Defender product family during this week’s Ignite event. The hyperscaler introduced Defender for DevOps and previews of Cloud Security Posture Management (CSPM) as part of Microsoft Defender for Cloud, its cloud-native application protection platform (CNAPP) portfolio.
Microsoft rebranded its Azure Security Center and Azure Defender into Defender for Cloud last year, which includes its Cloud Workload Protection Platform (CWPP) and CSPM capabilities to protect workloads on-premises, in Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP), the company claims.
“It's our comprehensive cloud-native application security platform, uniquely powered by intelligence generated from trillions of signals each day in the cloud, along with insights from 1000s of the best security researchers in the industry,” Microsoft CVP of Cloud Security Shawn Bice said during the event.
As customers need comprehensive visibility and a simplified way of remediating issues across all of their multicloud assets, the company added the new CSPM for agentless scanning and attack path analysis, built on Microsoft’s existing posture management capabilities and a new intelligent cloud security graph, according to Bice.
“These capabilities help you cut through the noise by focusing on reducing risks and strengthening your posture across your entire environment,” he added.
Microsoft Unifies DevOps Security ManagementMicrosoft’s vision with cloud security is to span from code to cloud, Bice noted. “You must start earlier in the development lifecycle. Start at the code itself and shift left.”
That’s why the tech giant announced the public preview of its Defender for DevOps, which is designed to help security teams unify DevOps security management across multi-pipeline and multicloud environments.
The new service integrates with GitHub Advanced Security for automated workflows across developer tools such as GitHub and Azure DevOps.
“Customers need to connect security and DevOps teams more effectively together to help developers bake security into the experience earlier and remediate issues in the code itself,” Shawn said.
Comments